Input validation vulnerability in WP Customize Login 1.1

The WP Customize Login plugin for WordPress is vulnerable to a type of attack called Stored Cross-Site Scripting. This attack can be done if the version of the plugin is 1.1 or lower. An attacker who has access to the WordPress website can inject malicious code into the website, which will run whenever anyone visits the website. This malicious code can be used to steal information or do damage. To protect against this type of attack, make sure you update the plugin to the latest version.

Detected in:

WP Customize Login open vulnerable versions: >= * <= 1.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.